Skip to content

SB 690 CIPA law signed: pen register claims go AG-only in 2027

Filip LuchianencoUpdated 6 min read

Last updated: 2026-10-02

On 2026-09-30 Governor Newsom approved SB 690 (Caballero), chaptered the same day as Chapter 976, Statutes of 2026. SB 690 amends Penal Code § 637.2, the private right of action in the California Invasion of Privacy Act (CIPA), so that a § 638.51 pen register or trap and trace claim against a private actor over conduct "on an internet website, online application, or mobile application" can be brought only by the Attorney General. The change is operative from 2027-01-01 and applies to pending claims in actions commenced in the two years before; wiretap (§ 631) and eavesdropping (§ 632) claims keep their private right of action.

What does SB 690 change in CIPA?

SB 690 adds subdivision (d) to Penal Code § 637.2 and makes subdivisions (a) and (b) subject to it. From the chaptered text:

An action against a private actor for a violation of Section 638.51 alleged to arise from conduct occurring on an internet website, online application, or mobile application may be brought under this section only by the Attorney General.

SB 690 amends one section; the bill title reads "An act to amend Section 637.2 of the Penal Code". The remedy in § 637.2(a) stays at the greater of "Five thousand dollars ($5,000) per violation" or three times actual damages; the Assembly Privacy and Consumer Protection Committee analysis describes the Attorney General as pursuing these violations "using the remedies currently provided in CIPA's right of action." The prohibition in § 638.51(a) and the criminal penalty in § 638.51(c) keep their current text.

The sponsor, the Alliance for Legal Fairness, told the committee that about 600 CIPA lawsuits had been filed against California businesses when its effort began in early 2025 and that "just 18 months later, that number has exploded to 4,000" (committee analysis, page 6). The figure is the sponsor's; the analysis gives no split by CIPA section.

Newsom's signing message dated 2026-09-30 says the measure "addresses the vexatious use of CIPA lawsuits and demand letters to extract settlement money from small businesses," and adds that "additional work in this area is needed, as CIPA contains other decades-old statutes that are also susceptible to abuse by overly aggressive litigants." The message continues: "I urge the Legislature to take this on next year to ensure a fair balance between protecting private information and preventing rapacious litigation."

When does SB 690 take effect, and is it retroactive?

The bill status page lists it as non-urgency, and California Constitution article IV, § 8(c)(1) puts the effective date of such a statute "on January 1 next following a 90-day period from the date of enactment of the statute." For SB 690, enacted on 2026-09-30, that date is 2027-01-01. Subdivision (d)(2) of § 637.2 makes the change retroactive (chaptered text):

The amendments to this section by Senate Bill No. 690 of the 2025–26 Regular Session apply retroactively to any pending claim in an action commenced within two years before the operative date of that legislation.

The committee analysis describes the window as "pending litigation filed within the two-year window before January 1, 2027" and states that the amendments "would not affect any case for which a final judgment has been entered." The same page says the bill's severability clause (SEC. 2) was added "in view of possible constitutional challenges to the retroactivity provisions." The bill text leaves "pending claim" and "commenced" undefined; how the two terms apply to removed cases, amended complaints and cases on appeal is for the courts to decide.

What happened to the "commercial business purpose" exemption?

The Senate passed the bill 35 to 0 on 2025-06-03 in its 2025-05-29 form, which added this subdivision to § 637.2 (shown struck in the committee's amendment text):

This section does not apply to the processing of personal information for a commercial business purpose.

The committee analysis for the 2026-07-01 hearing called that version "too blunt of a solution" because "it broadly exempts any 'commercial business purpose' as defined by the California Consumer Protection Act [sic] (CCPA) from all civil and criminal liability under CIPA." Amendment 1, which the bill's author accepted, reads: "Strike all changes to sections 631, 632, 632.7, and 638.50, removing those sections from the bill." The Assembly struck the exemption in July 2026, passed the amended bill 66 to 0, and the Senate concurred 39 to 0, both votes on 2026-08-28.

What changes and what stays in CIPA after SB 690?

CIPA provision What it covers After SB 690 (operative 2027-01-01)
§ 638.50 Defines "pen register" and "trap and trace device": a device or process for "dialing, routing, addressing, or signaling information... but not the contents of a communication" Text unchanged; the 2025 amendments to it were struck in July 2026
§ 638.51 Bars installing or using a pen register or trap and trace device without a court order; criminal penalty of a fine up to $2,500, imprisonment up to one year in county jail or under § 1170(h), or both Text unchanged; the prohibition and criminal penalty remain
§ 637.2 (pen register claim, website or app conduct, private actor) Private action for $5,000 per violation or treble damages, plus injunction Attorney General only; applies to pending claims in actions commenced in the prior two years
§ 637.2 (pen register claim, other conduct) Same private action Private action remains
§ 631 (wiretap) Reading or learning "the contents or meaning" of a communication in transit without consent of all parties, and aiding it Text unchanged; private action under § 637.2 remains
§ 632 (eavesdropping) Recording or eavesdropping on a "confidential communication" without consent of all parties Text unchanged; private action under § 637.2 remains
§ 632.7 (cellular recording) Intercepting or receiving and recording a communication between two cellular or cordless telephones, or between either and a landline telephone, without consent of all parties Text unchanged; the 2025 amendments to it were struck in July 2026

Sources: chaptered SB 690 text; Penal Code sections as published on leginfo.legislature.ca.gov, retrieved 2026-10-02; committee analysis, Amendment 1.

Do CIPA sections 631 and 632 still allow private claims?

Yes. SB 690 leaves §§ 631 and 632, and the private right of action for them under § 637.2, unchanged. Section 632 covers recording or eavesdropping on a "confidential communication" without the consent of all parties. Section 631 is the contents statute. From the committee analysis, page 18: "Unlike the pen register statute, which applies to information about communications, Section 631 prohibits surreptitious interception of the content of communications."

Where contents begin is case law. The committee analysis quotes the 2023 Southern District of California decision in Greenley v. Kochava: "The statute does not provide clarity on the definition of 'contents,' and so courts have penciled in a dividing line. On one hand, courts have found that the contact information of the communicating parties and the geolocation of the communicating parties are not the 'contents' of a communication under Section 631. [Citations.] On the other hand, information about particular activity conducted and search terms used on an app qualify as the 'contents' of communication."

What does SB 690 mean for mobile app and SDK cases?

Greenley was a suit over a data broker's SDK in third-party apps. The committee analysis cites it as the decision whose reasoning most federal district courts in California have followed in denying motions to dismiss pen register claims.

On 2026-04-29 Judge Araceli Martínez-Olguín denied InMobi's motion to dismiss in Caldwell v. InMobi Pte. Ltd., No. 25-cv-09977-AMO (N.D. Cal.). The plaintiff alleges that InMobi's SDK in a dating app on his Android device sent "timestamped geolocation data, mobile advertising IDs, IP addresses, and other device fingerprinting details" to InMobi, and pleads a § 638.51(a) claim alongside intrusion upon seclusion and California constitutional privacy claims. These are allegations at the pleading stage. The order predates SB 690, and this post covers the Caldwell docket only up to that order; how § 637.2(d)(2) applies to the Caldwell pen register count is open.

In an app case pleaded like Caldwell, from 2027-01-01 only the Attorney General may bring the § 638.51 count under § 637.2. The intrusion upon seclusion and constitutional privacy counts pleaded beside it arise outside CIPA, and SB 690 leaves them as they are. For a wiretap count under Section 631, one question is what the SDK received: identifiers and routing fields, or the contents of what the user typed, searched or sent.

Rodriguez v. Google is an SDK case tried on claims outside CIPA, among them the Comprehensive Computer Data Access and Fraud Act (CDAFA). Per the court's 2026-01-30 order (Case No. 20-cv-04688-RS, N.D. Cal.), the jury found Google "not liable for violating CDAFA but liable for invasion of privacy and intrusion upon seclusion."

When I run an app on a test device, the network capture logs each request with its timestamp, destination host and payload next to the moment the consent prompt was shown and tapped. That record shows whether a search term, chat message or form field was sent to a third-party SDK host, and whether before or after the tap. The capture of the running app decrypts payloads where TLS interception works on the test device; connections from an app that pins its certificates are a gap in that capture. Whether a given field is "contents" under § 631, or "dialing, routing, addressing, or signaling information" under § 638.50, is a legal characterization; the capture records the field and the host it was sent to.

A static scan shows which SDKs are present in the build, the permissions the app declares and how its consent flow is built. Presence in a binary is a lead; transmission is established only by a capture, as set out in the limits of a scan. The trust checks list what a scan records for each app in the public app index, and every finding cites its file and line.

I run these scans and captures for lawyers and for researchers working with lawyers. Sign up for a CanITrustThat account to run your own research, or let us run an investigation for you.

App privacy law, applied to real apps.

Posts on new laws, fines and studies, and teardowns of the apps those laws apply to.

How we use your address: privacy notice. Prefer a feed reader? Use the RSS feed.